Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
| Software | From | Fixed in |
|---|---|---|
| cvxopt_project / cvxopt | - | 1.2.6.x |
| fedoraproject / fedora | 34 | 34.x |
cvxopt
|
- | 1.2.7 |